{"rewrite":{"id":"r_183443ce6b6be60b0d49cc62","clusterId":"c_b69089346137251cba7f65f7","slug":"red-hat-npm-packages-compromised-by-credential-stealing-worm","model":"deepseek-v4-flash","headline":"Red Hat NPM Packages Compromised by Credential-Stealing Worm","summary":"Security firm Aikido reported that 32 packages under Red Hat's official npm channel were backdoored with a worm malware named Miasma, totaling 116,991 weekly downloads. The attack exploited a compromised employee GitHub account and GitHub Actions OIDC to publish malicious packages that steal cloud and CI credentials and attempt to spread to other repositories.","whyItMatters":"The breach of Red Hat's own npm publishing pipeline shows that even official, trusted package channels can be weaponized through compromised developer accounts and automated CI workflows, making supply chain attacks harder to detect.","webCardHtml":"\u003cp\u003eThe attack chain began when an attacker compromised a Red Hat employee's GitHub account, then injected malicious isolated commits into multiple development repositories, bypassing code review. A malicious GitHub Actions configuration file was added that automatically executed package publishing, obtaining short-lived credentials from GitHub and registering backdoored packages through npm's official route. The malware, a 4.2 MB obfuscated JavaScript file, executed on npm install and searched for GitHub Actions secrets, AWS, Google Cloud, and Azure credentials, SSH private keys, npm and PyPI tokens, Docker credentials, and .env files. Stolen data was encrypted and exfiltrated, and the worm attempted to backdoor other accessible packages and repositories.\u003c/p\u003e\u003cp\u003eRed Hat said affected packages were limited to internal development use and not published to customers via console.redhat.com, with no confirmed impact on customer or partner environments. However, anyone who installed the packages should assume their development endpoints or CI/CD environments are compromised and immediately rotate CI secrets, cloud credentials, SSH keys, and npm tokens.\u003c/p\u003e","blueskyPost":"Miasma used a compromised Red Hat employee GitHub account and OIDC tokens to publish malicious packages. The worm then stole cloud credentials and self-replicated across repositories.","twitterPost":"Miasma exploited Red Hat's own GitHub Actions OIDC to publish backdoored packages, then stole cloud credentials and spread to other repos.","threadsPost":"Red Hat's official NPM channel hosted 32 backdoored packages delivering the Miasma worm. The attack chain started with a compromised employee GitHub account, then used GitHub Actions OIDC to publish malicious versions. Miasma stole cloud and CI credentials and attempted to spread to connected repositories.","newsletterBlurb":"Security firm Aikido reported that 32 packages under Red Hat's official npm channel were backdoored with a credential-stealing worm named Miasma. The attack exploited a compromised employee GitHub account and GitHub Actions OIDC to publish malicious packages. Red Hat removed the affected packages and said no customer environments were impacted, but recommends rotating all CI secrets and cloud credentials.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260602-red-hat-npm-packages-miasma/\",\"title\":\"Dozens of packages backdoored through Red Hat's official npm channel\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":3872,"outputTokens":646,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1780376127,"createdAt":"2026-06-02T04:49:10.000Z","publishedAt":"2026-06-02T04:53:27.000Z","updatedAt":"2026-06-02T04:53:27.000Z"},"cluster":{"id":"c_b69089346137251cba7f65f7","canonicalTitle":"Red Hatの公式npmチャンネルを通じて数十個のパッケージにバックドアが仕込まれていたと判明","representativeArticleId":"a_1fa31f41300b88d6ce4719ea","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-02T04:10:00.000Z","lastSeenAt":"2026-06-02T04:10:00.000Z","updatedAt":"2026-06-02T04:53:27.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260602-red-hat-npm-packages-miasma/","title":"Red Hatの公式npmチャンネルを通じて数十個のパッケージにバックドアが仕込まれていたと判明"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["32 packages under Red Hat's official npm channel were backdoored with a worm malware named Miasma, totaling 116,991 weekly downloads.","The attack exploited a compromised employee GitHub account and GitHub Actions OIDC to publish malicious packages.","Red Hat said affected packages were limited to internal development use and not published to customers via console.redhat.com, with no confirmed impact on customer or partner environments.","Anyone who installed the packages should assume their development endpoints or CI/CD environments are compromised and immediately rotate CI secrets, cloud credentials, SSH keys, and npm tokens."]}
